For business leaders with responsibility for Control of Major Accident Hazards (COMAH), cyber security is fast becoming a top priority. The Health & Safety Executive (HSE) has responded to cyber attacks on energy, water and industrial sites in Europe and the USA by instructing its inspectors to double down on compliance with its OG86 standard for protection of industrial automation and control systems.
Non-compliance carries severe legal and business consequences. The courts have the power to impose fines with no upper limit, and the HSE has demonstrated willingness to pursue substantial penalties and to hold senior executives personally liable. Enforcement action can also include prohibition notices that suspend or shut down operations entirely.
However, achieving compliance with cyber security standards is often very challenging, due to the inherent inflexibility and vulnerability of operational technology (OT). The good practice and tools used to monitor, secure and recover from cyber incidents in IT networks are often ineffective or can cause catastrophic failure if applied to your OT networks.
Due to the long operational life of OT systems and networks, they are seldom properly documented, so the extent and nature of your cyber risk is largely unknown, particularly knock-on effects and the impact of taking compromised systems offline.
The HSE requires an organisation’s cyber risk exposure to be “as low as reasonably practicable”. This means that you need to take a planned approach, ensuring you have evidence of informed and considered decision-making, particularly in the event of an enforcement situation.
A major obstacle to achieving this is the very large skills gap between IT and OT; working safely with OT systems requires years of experience, while cyber security is fast-moving, complex and also challenging to master.
Arcanum provides practical help with cyber security for COMAH site operators. Our staff are highly qualified and experienced in cyber security for OT, from manufacturing to energy generation.
HSE requirements for COMAH sites
In recent years, there have been increasingly serious cyber attacks on organisations in energy generation, water supply, food production and other critical sectors, across Europe and the USA. The implications can be profound: hackers have been able to take control of chlorine dosing in a water works; a critical petroleum supply was shut down for several days; and huge sums of money have been paid in ransom.
In the UK, the HSE has responded by announcing an increased focus on compliance with cyber security standards across all COMAH sites.
You can use any appropriate framework to demonstrate your cyber security to the HSE, but the benchmark for cyber security within the remit of COMAH regulations is arguably the HSE’s own operational guidance, ‘OG86 – Cyber Security for Industrial Automation and Control Systems’. This is based on the UK National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF) and ISA/IEC 62443 series of standards.
The HSE requires COMAH sites to achieve the ‘basic’ level of maturity, which means demonstrating that your exposure to cyber risk is “as low as reasonably practicable”.
In practice this means that you need a rational, systematic approach to risk management. In enforcement scenarios, inspectors will not only scrutinise the condition of your OT environment, but they will also dissect the logic behind your decisions.
Particular challenges in OT
The HSE openly acknowledges a hard truth: securing OT networks and industrial control systems is vastly more complex and challenging than IT systems.
Unlike IT systems, which are designed for agility and tolerate regular downtime for updates and patching, OT environments are engineered for continuity, without interruption. Safety, uptime, and physical processes are tightly interwoven, leaving little room for changes or automated interventions.
Cyber security tools and practices that are prevalent in IT, including automated patching, real-time threat detection, and invasive network scanning techniques can be dangerously incompatible with OT. They risk triggering false alarms, disrupting critical operations, or even compromising safety-critical systems.
Add to that the fragmented architectures, proprietary protocols, and legacy equipment still in active use, and it becomes clear: applying IT-style security to OT isn’t just ineffective, it can be very dangerous.
Limitations of separation strategies
For many years, the cyber security vulnerabilities within OT networks have been managed with a well-planned separation of IT and OT per the Purdue model: Industrial systems have been organised into distinct layers, from business networks at the top down through control systems to field devices, with security zones and controlled access points between each layer.
However there has been rapid change in how vendors connect and provide support remotely, as well as adoption of technologies like Industrial Internet of Things (IIoT) and data historians, which can bridge the ‘air gap’ between layers of that network architecture. With increasing IT/OT convergence, such as centralised dashboards and cloud-based analytics, new pathways are emerging between operational and corporate networks.
Even a temporary bridging between the OT and IT networks can provide the opportunity required by a sophisticated, patient attacker to collect intelligence about your systems, spread a malicious payload more widely or install more persistent connections.
With this evolution in the threat landscape, it is no longer reasonable to depend on system isolation as a strategy; compliance with OG86 and other standards requires more sophisticated cyber security measures within your OT network.
Negotiating multiple standards and frameworks
COMAH sites already have established processes for managing risk – safety standards for instrumentation systems, hazard and operability studies (HAZOP) for process risks, and IT security for corporate networks. Now, OG86 requires you to demonstrate cyber security across these same systems, but from a completely different perspective.
Many COMAH operators also face additional sector-specific requirements. For example, oil and gas companies must navigate offshore safety regulations and environmental permitting, and sites classified as Operators of Essential Services must also comply with NIS regulations.
Without careful planning, there is a real risk of duplicating resources on separate risk assessments for the same systems, implementing potentially conflicting controls, and difficulty demonstrating how established safety procedures also address cyber risks.
The best approach involves mapping OG86 requirements against your existing safety and process risk frameworks, so that cyber risks are managed within established governance structures rather than as a separate compliance burden.
Planning your response to cyber incidents in OT
Incident response plans are a key part of the HSE’s cyber security requirements. However, unlike IT systems that can be isolated and then restored from a backup, OT incident response must balance cyber security concerns with the fundamental need to maintain safe operations.
The complex interactions within industrial processes and their control systems means you need to plan your incident response carefully, so you have confidence to act quickly and decisively when necessary.
You must also plan for scenarios where safety systems themselves may be compromised – determining what manual overrides are available, what alternative monitoring you can rely on, and at what point the safest option is a controlled shutdown rather than continued operation.
Where your plans call for restarting a process or system, it is important to consider the specific steps required to bring it back into operation. In some cases, this may require particular materials or even specialist equipment from a third party for the recommissioning.
Working with incomplete information
Effective incident response planning requires a comprehensive understanding of your OT assets, including the physical hardware, operating systems, configurations and connectivity.
Unlike IT networks, you also need to be clear about which systems control which physical processes, what additional safety systems are in place, what the manual overrides are, and how these systems interact during both normal operations and emergency scenarios.
However, most OT systems have developed and evolved over extended periods, often as discrete projects with little consideration for the wider network. As such, the documentation of OT networks is often fragmented, incomplete and out of date – with some critical knowledge existing only in the heads of long-serving engineers.
Building the complete picture is challenging and resource intensive. The automated discovery tools used in IT networks are often ineffective in OT environments or risk disrupting critical systems. Instead, asset discovery often requires hands-on investigation, specialised industrial networking expertise, and considerable time to capture undocumented knowledge from key personnel.
The OT cyber security skills gap
A major obstacle to fully understanding and addressing the cyber vulnerabilities within your OT assets is the substantial and widespread skills gap between IT and OT. Increasingly difficult is then mapping OT assets to loss of essential and major accident consequences.
Industrial control and automation systems are highly specialised and working safely within these 24/7 operational environments requires years of experience. But at the same time, the sophistication and fast-changing nature of cyber threats means that your OT specialists would require years of training and experience to reach the skill levels reasonably required for securing a COMAH site.
To properly understand your OT systems and to work out the practical implications of the vulnerabilities, you need people who have substantial, hands-on operational experience as well as specialist OT security skills.
At Arcanum we provide practical support and expertise to operators of COMAH sites. We are experts in cyber security for OT with extensive experience in mission-critical environments, from 24/7 manufacturing to transport networks and nuclear power generation.
We work with your safety compliance teams to ensure that cyber risks are properly integrated into your existing risk management processes. Rather than treating cyber security as a separate technical issue, we help translate cyber vulnerabilities into the same business risk language your enterprise risk management systems already understand and monitor. This approach ensures cyber security gets appropriate priority and resources within your established governance structures.
Our team holds the highest cyber security qualifications and is trusted to provide services on behalf of UK government agencies and cyber security bodies. We build long-term relationships with our clients, helping them meet immediate regulatory and security needs while building toward ever more efficient and cost-effective cyber security.
Find out more
If you would like to explore the ways in which Arcanum could help you protect your operation from cyber threats and ensure compliance with HSE requirements, please read about our services for COMAH sites or get in touch.